Impact
The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin allows an authenticated user with Subscriber or higher privileges to modify the shipping method, pickup‑point metadata, and shipping address of any WooCommerce order because the wp_ajax_lpc_order_affect handler performs no capability check or nonce verification before applying the changes. This is a classic Missing Access Control flaw (CWE-862) that can change how a customer’s order is shipped, potentially causing financial loss or operational disruption.
Affected Systems
WordPress sites running the iscpcolissimo Colissimo shipping methods for WooCommerce plugin version 2.9.0 or earlier are affected. Any user with Subscriber‑level access or higher can trigger the vulnerable Ajax action to alter shipping details of arbitrary orders.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1 % suggests a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Because the flaw requires authentication via Ajax and does not provide code execution, the impact is limited to the modification of shipping data, which can still cause financial or reputational damage for the site owner.
OpenCVE Enrichment